Originally published on AI Tech Connect.
What you need to know Here is the conversation that tells you a platform has an identity problem. Something odd shows up in an audit log at two in the morning — a bulk export, a write to a ledger that should have been read-only, a supplier record changed twice in three seconds. Someone asks the only question that matters: which agent did that? And the answer is that nobody can tell, because eleven agents share one service account, so every line in the log carries the same actor. The second question — can we switch that one off? — has an equally bad answer: not without breaking the other ten. That failure is not a scoping failure. You can have beautifully narrow permissions and still be unable to attribute, isolate or explain an action. Scoping is covered elsewhere on this site, in detail:…
Top comments (0)